Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 112555 - www-apps/xoops: Arbitrary local file inclusion
Summary: www-apps/xoops: Arbitrary local file inclusion
Status: RESOLVED UPSTREAM
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL: http://www.securityfocus.com/archive/...
Whiteboard: ~2 [upstream+]
Keywords:
Depends on:
Blocks:
 
Reported: 2005-11-14 14:36 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2006-01-03 07:11 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-11-14 14:36:51 UTC
Reported on Bugtraq: 
 
[1]XOOPS 2.2.3 Final arbitrary local inclusion 
[2]XOOPS WF-Downloads module v 2.05 SQL Injection / Administrative credentials 
disclousre / Remote commands execution
Comment 1 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-11-14 14:37:12 UTC
web-apps please advise. 
Comment 2 Thierry Carrez (RETIRED) gentoo-dev 2005-11-16 07:47:23 UTC
Nothing upstream afaict, To be confirmed...
Also we probably don't provide the WF-Downloads module in Portage.
Comment 3 Stuart Herbert (RETIRED) gentoo-dev 2005-11-20 02:05:50 UTC
Vulnerability #1 relies on 'register_globals' set to 'on'.  Default installation
on Gentoo is to set this to 'off'; however, because the majority of PHP
applications are "legacy" applications, many of our users will have changed the
default setting of 'register_globals' to 'on'.

Workaround is to switch 'register_globals' to 'off'.  There's no sign of
anything from UPSTREAM yet.

We're not vulnerable to the second one; like Koon said, we don't ship the
WF-Downloads module.

Best regards,
Stu
Comment 4 Thierry Carrez (RETIRED) gentoo-dev 2006-01-03 07:11:47 UTC
Let's close this one. register_globals=On is evil anyway.
Feel free to reopen if you disagree.